CVE-2026-108596
EUVD-2026-9639610.10.2026, 19:16
OpenLIT 2.1.0 contains an authorization bypass vulnerability that allows authenticated users to read other projects' telemetry by supplying a forged x-openlit-project-id header. Attackers who know a victim project id and database config id can query the trace read API to obtain traces including LLM prompts and completions.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| openlit | openlit | 𝑥 ≤ 2.1.0 | CNA |
Common Weakness Enumeration
References